Security Vulnerabilities

The latest Security Vulnerabilities

NewsSecurity Vulnerabilities

ASUS Business Manager Service Client-Side Authentication Local Privilege Escalation Vulnerability (CVE-2026-7480)

– This vulnerability allows local attackers to escalate privileges on affected installations of ASUS Business Manager.

Read More
NewsSecurity Vulnerabilities

Cisco Webex Meetings Cross-Site Scripting Vulnerability (CVE-2026-20233)

– A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this vulnerability in the Webex Meetings service, and no customer action is needed.

Read More
NewsSecurity Vulnerabilities

Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability (CVE-2026-20230)

CVE number – CVE-2026-20230 A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management

Read More
NewsSecurity Vulnerabilities

Exploitation of Critical SQL Injection Vulnerability in Drupal (CVE-2026-9082)

– A critical vulnerability in the Drupal content management system is being actively exploited, prompting the US Cybersecurity and Infrastructure Security Agency (CISA) to add it to its Known Exploited Vulnerabilities (KEV) catalogue.

Read More
NewsSecurity Vulnerabilities

TrendAI Vision One Security Agent Origin Validation Error Local Privilege Escalation Vulnerability (CVE-2026-34927)

– This vulnerability allows local attackers to escalate privileges on affected installations of TrendAI Vision One Security Agent.

Read More
NewsSecurity Vulnerabilities

LiteSpeed User-End cPanel Plugin privilege escalation vulnerability (CVE-2026-48172)

CVE number – CVE-2026-48172 LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the

Read More
NewsSecurity Vulnerabilities

Cisco Secure Workload Unauthorized API Access Vulnerability (CVE-2026-20223)

– A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role.

Read More
NewsSecurity Vulnerabilities

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability (CVE-2026-20182)

– A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.

Read More
NewsSecurity Vulnerabilities

Siemens Simcenter Femap IPT File Parsing Memory Corruption Remote Code Execution Vulnerability (CVE-2025-12659)

– This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Simcenter Femap.

Read More
NewsSecurity Vulnerabilities

Apple macOS CoreSymbolication Out-Of-Bounds Read Information Disclosure Vulnerability (CVE-2026-28918)

– This vulnerability allows remote attackers to disclose sensitive information on affected installations of Apple macOS.

Read More